This Privacy Policy explains how Niogin LLC (“Niogin”, “we”, “us”, or “our”) handles personal data in connection with Shoptimizr at https://shoptimizr.com, the Shoptimizr dashboard, the Shoptimizr Shopify app, our storefront web pixel and theme extensions, and related professional services.
Shoptimizr is operated day-to-day by Niogin (Pvt) Ltd, 02, 6th Lane, Colombo 03, Sri Lanka, as an affiliate of Niogin LLC. Niogin LLC is formed under the laws of the State of Wyoming, United States and maintains a principal office in Dallas, Texas, United States.
This policy is written to meet the transparency requirements of the EU and UK GDPR, Sri Lanka’s Personal Data Protection Act, No. 9 of 2022, and analogous laws where they apply. It is not a certification, and it does not claim that every engineering control described in our product roadmap is already live.
01Who we are
Contracting entity. Niogin LLC is the party that contracts with merchants and is the controller (or, where we process a merchant’s customer data, the processor) named in this policy.
Operator. Niogin (Pvt) Ltd hosts, develops, and supports the product on Niogin’s infrastructure. It processes personal data as an affiliate processor of Niogin LLC.
We have not appointed a data protection officer. We have not appointed an EU or UK representative under GDPR Article 27. Privacy requests should be sent to [email protected].
02Scope
This policy covers:
- visitors to shoptimizr.com and related marketing pages;
- users who request a magic link, sign in with Google Workspace (Niogin staff), or are invited as a client;
- merchants who install the Shoptimizr Shopify app, connect Google Analytics 4 or Klaviyo, or receive services-led onboarding;
- storefront visitors of a merchant’s Shopify store when the Shoptimizr web pixel, checkout UI, or experiment blocks are active (we process this data as the merchant’s processor — see section 13).
It does not replace the merchant’s own storefront privacy notice, Shopify’s policies, Google’s policies, or Klaviyo’s policies.
03Controller and processor
We are a controller of personal data about people who deal with us directly: website visitors, account users, invoicing contacts, and people who email us about early access.
We are a processor of personal data about a merchant’s store customers, visitors, and (where connected) email-list members. The merchant is the controller. Our processing of that data is described in the Data Processing Addendum and is limited to providing Shoptimizr: ingest, diagnostics, attribution, experiments, LLM visibility, and related support.
If you are a shopper on a brand’s store and want to access or delete data about you, contact that brand. They can use Shopify’s customer-data tools; we honour Shopify’s mandatory customers/data_request, customers/redact, and shop/redact webhooks as implemented today (see section 13 for current limits).
04Personal data we process
Account and website (controller)
- Name, work email, tenant membership, and role (owner, marketer, viewer, or Niogin staff role).
- Magic-link tokens (hashed), session JWT, and the readable user cookie used to render the UI.
- Google account identifiers for staff who sign in with Google Workspace (
hd=niogin.com). - Invite records and audit-log entries for mutating actions in the dashboard.
- Correspondence you send to our contact addresses, including early-access requests.
- Approximate technical data from our web server and, where Google Fonts load, an IP address shared with Google to deliver fonts on the marketing site.
Store and analytics (processor)
- Shopify shop domain, install tokens, scopes, theme assets we deploy, and webhook payloads (orders, checkouts, customers as permitted by installed scopes).
- Web pixel events: page URL, referrer, UTM and click IDs (gclid, fbclid, and similar), product and cart context, checkout funnel events, and a first-party visitor identifier (
_rb_vid). - Checkout and order email addresses. We store a per-tenant salted SHA-256 hash for identity stitching. Checkout and order payloads may also contain the email in raw form in event JSON until we finish stripping those fields.
- Session, touchpoint, and attribution records keyed by visitor ID.
- GA4 property identifiers, OAuth tokens, and aggregated traffic/purchase reports the merchant authorises.
- Klaviyo campaign and segment data the merchant authorises, including hashed emails used to join visitors to segments.
- Catalog, content, and diagnostic snippets used for LLM visibility and hypothesis generation. Those workloads may be sent to a language-model gateway (currently OpenRouter).
- Experiment assignments, variant payloads, and conversion events tied to visitor IDs.
We do not intentionally collect special-category data (health, religion, and similar). Store payloads may incidentally include such data if a merchant’s checkout or notes contain it; we do not use it for profiling of that kind.
05Sources
- You, when you submit a form, sign in, or configure integrations.
- Shopify, via OAuth, Admin API, webhooks, and Customer Events (web pixel).
- Google, via GA4 APIs and, for Niogin staff, Google Workspace sign-in.
- Klaviyo, when a merchant connects that integration.
- The storefront itself (pixel, theme app extension, checkout UI, app proxy).
- Our own logs, job runner, and support tools.
06Purposes and legal bases
Where GDPR or the UK GDPR applies to processing we control, we rely on the bases below. Where we are a processor, the merchant is responsible for its own legal basis vis-à-vis shoppers.
| Purpose | Legal basis (controller) |
|---|---|
| Create and authenticate accounts; send magic links; keep you signed in | Contract (Art. 6(1)(b)); strictly necessary cookies |
| Provide the dashboard, onboarding, and contracted professional services | Contract |
| Secure the service, prevent abuse, keep an audit trail | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Respond to early-access and support email | Legitimate interests; steps prior to contract |
| Improve product reliability using aggregated usage of the dashboard | Legitimate interests |
| Comply with Shopify Partner, tax, and bookkeeping duties | Legal obligation (Art. 6(1)(c)) |
Storefront tracking on a merchant’s domain is processing we perform as processor. The merchant must have a lawful basis, including ePrivacy/cookie consent where required. Shoptimizr does not currently read the merchant’s consent-management platform or Shopify customer-privacy signals before setting _rb_vid or sending pixel events. We intend to honour those signals in a later release. Until then, merchants selling to individuals in the EEA, UK, or Switzerland are responsible for configuring their own CMP and for deciding whether to activate the pixel.
09International transfers
Personal data is processed in Sri Lanka (Niogin-operated infrastructure) and countries where our subprocessors operate, including the United States and the European Economic Area. Transfers from the EEA or UK to Sri Lanka and the United States are restricted transfers under GDPR Chapter V.
Where we are the controller, we rely on one or more of: an adequacy decision if one applies; the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where required); and, for US organisations that participate, the EU-US Data Privacy Framework. Niogin (Pvt) Ltd processes data in Sri Lanka under intra-group instructions from Niogin LLC.
Merchants who are themselves controllers remain responsible for their own transfer assessments when they send EEA/UK shopper data to Shoptimizr.
10Retention
- Raw Shopify webhook objects in object storage: 30 days.
- Normalised pixel/session/event and attribution touchpoint rows: 24 months, then deleted in batches.
- Finished background-job rows: about 14 days.
- Shopify order rows and several derived aggregates (for example RFM and hidden winners) are kept while the tenant remains active; they are not yet purged by the same 24-month job.
- Account data: for the life of the account, then as needed for legal claims and bookkeeping.
- Magic-link tokens: until used or expired (minutes, not days).
On app uninstall we mark the Shopify install inactive immediately. Shopify later sends shop/redact. We are still completing an automated full-shop wipe; residual store data may remain in operational stores and backups until that work ships. Tenant owners may also request a data export. Email [email protected] to escalate deletion.
11Security
We use TLS in production, tenant isolation (including PostgreSQL row-level security), hashed magic-link tokens, per-tenant salts for email hashes, access control by role, and encryption helpers for selected secrets. Shopify access tokens are stored in our application database. We do not claim SOC 2, ISO 27001, or “GDPR certified” status.
No method of transmission or storage is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authority as required by law and, where we are a processor, the merchant without undue delay as set out in the DPA.
12Your rights
If you are in the EEA, UK, or another jurisdiction with similar rights, you may have the right to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent. You may also lodge a complaint with your local supervisory authority (for example an EU member-state SA, the UK ICO, or the Data Protection Authority of Sri Lanka).
Account users. Email [email protected]. We do not yet offer a self-service download/delete control in the dashboard. Tenant-level export is available to authorised owners.
Store customers. Contact the merchant. We assist the merchant through Shopify’s customer webhooks. Customer-data export packages are delivered to the merchant’s owner emails, not to the shopper directly.
We may need to verify your identity and may refuse requests that are manifestly unfounded, excessive, or that would disclose another person’s data.
13Store customers and Shopify
When a merchant installs Shoptimizr they instruct us to process shopper and store data to provide conversion intelligence. That processing is documented in the DPA.
Shopify Partner compliance webhooks:
customers/data_request— we compile data we hold for the identified customer and send a download link to the merchant’s owners.customers/redact— we redact or delete customer-linked sessions, identities, and related rows we currently cover in that job.shop/redact— we currently mark the shop uninstalled. A complete deletion of remaining shop data after uninstall is on our engineering backlog.
Experiment and exit-intent features also use _rb_vid without a separate consent gate in the pixel. See section 6.
14Children
Shoptimizr is a B2B product. It is not directed at children under 16, and we do not knowingly create accounts for them. If you believe we have collected personal data from a child, contact us and we will delete it.
15Other privacy laws
California and similar US state laws. We do not sell or share personal information as those terms are defined for cross-context behavioural advertising of our own marketing site. We do not yet expose an automated “Do Not Sell/Share” or CPRA request portal. California residents may email the address below; we will handle the request manually.
Sri Lanka PDPA. Niogin (Pvt) Ltd is a controller of website enquiry data it collects in Sri Lanka and a processor of merchant customer data it handles for Niogin LLC.
India DPDP. We do not currently operate a dedicated Data Fiduciary grievance mechanism beyond the contact below.
16Changes
We may update this policy. The “Last updated” date will change. Material changes will be posted on this page. Continued use of the service after the effective date of a change constitutes acceptance of the revised policy to the extent permitted by law. Where consent is required, we will ask for it.
17Contact
Privacy requests: [email protected]
Niogin LLC
Formed in the State of Wyoming, United States
Principal office: Dallas, Texas, United States
Niogin (Pvt) Ltd
02, 6th Lane, Colombo 03, Sri Lanka
Related documents: Terms of Service and Data Processing Addendum.